Data processing agreement
Version 2026-09-28. This agreement is made under Article 28 of Regulation (EU) 2016/679 (GDPR). It is part of the terms of service, and the School accepts it when registering. Terms defined there have the same meaning here. The Polish version prevails.
1. Parties
- Controller: the School that registered in DiveTheory.
- Processor: Bartlomiej Zubrzycki IT Services, Warszawa, NIP 9512298102, email divetheory@nopressurediving.com.
2. Subject, duration, nature, and purpose
- The Controller entrusts the Processor with processing personal data of its Students solely to provide the Service as described in the terms.
- Processing lasts as long as the School uses the Service, and ends as set out in section 10.
- Processing consists of storing, organising, displaying, and analysing the data (scoring answers and showing weak topics), sending emails, producing training-record documents, making backups, and deleting the data.
3. Data and data subjects
- Data subjects: the Controller's Students, including minors.
- Personal data: first name, last name, and email address; assigned courses and their language; progress in lessons; answers to quizzes and exams and their scores; weak topics; remediation tasks; the Instructor's assessments and notes; training records; the date and version of accepting the terms; technical data (IP addresses in logs, sign-in attempts).
- The Service is not meant for special categories of data (Article 9 GDPR). The Controller will not enter them, in particular health data such as medical questionnaire answers.
4. Controller's instructions
- The Processor processes the data only on the Controller's documented instructions. These are the terms, this agreement, and what the Controller does in the Service (for example adding a Student, assigning a course, or asking for deletion).
- If the Processor believes an instruction breaks data protection law, it tells the Controller at once.
- The Processor may process the data otherwise only where EU or Polish law requires it, and then tells the Controller first unless the law forbids that.
5. Processor's obligations
The Processor:
- ensures that everyone it authorises to process the data is bound by confidentiality;
- applies the security measures in Annex 1 (Article 32 GDPR), and keeps them up to date;
- helps the Controller, as far as it can, to answer data subjects' requests (Articles 15–22 GDPR), and passes on any request it receives directly within 7 days;
- helps the Controller meet its obligations under Articles 32–36 GDPR (security, breach notification, impact assessments, prior consultation), taking into account the information it has;
- notifies the Controller of a personal data breach without undue delay, and no later than 48 hours after becoming aware of it, with the information the Controller needs to report it;
- keeps a record of processing activities carried out for the Controller (Article 30(2) GDPR).
6. Sub-processors
- The Controller gives general authorisation to use sub-processors. Those in use when this version was published are listed in Annex 2.
- The Processor tells the Controller by email at least 14 days before adding or replacing a sub-processor. The Controller may object in that time; if the parties cannot agree, the Controller may end the agreement.
- The Processor imposes on each sub-processor data protection obligations no weaker than those in this agreement, and remains fully liable to the Controller for their performance.
7. Transfers outside the European Economic Area
Data is transferred outside the EEA only with safeguards under Chapter V GDPR: an adequacy decision (including the EU–US Data Privacy Framework) or the European Commission's standard contractual clauses.
8. Audits
- The Processor makes available to the Controller the information needed to show compliance with Article 28 GDPR, and answers written questions within 14 days.
- If the answers are not enough, the Controller may carry out an audit, itself or through an auditor bound by confidentiality, after at least 14 days' notice, during business hours, no more than once a year unless a breach has occurred, and at its own cost.
9. Liability
Each party is liable under Article 82 GDPR. Otherwise liability follows the terms of service.
10. End of processing
- The agreement ends when the School's account is closed or the agreement to provide the Service ends.
- Before the account is closed, the Controller may ask for a copy of its Students' data in a common electronic format.
- Within 30 days of the end, the Processor deletes the data, unless the law requires it to be kept. Backups that still contain the data are overwritten within a further 30 days.
- The Controller may also ask at any time for the data of individual Students to be deleted.
Annex 1: Security measures
- Encrypted connections (HTTPS) between users and the Service.
- Passwords stored only as salted hashes.
- The database runs on a server in the European Union and cannot be reached from the internet.
- Server access only by the Processor, with SSH keys; the server management panel uses two-factor authentication; security updates are installed regularly.
- Separation of Schools in the application: each School sees only its own Students; every page is available only to the roles that need it.
- Account lockout after repeated failed sign-ins, and limits on repeated form submissions.
- Daily database backups kept with a separate provider; restoring from a backup is tested.
- Error reports without IP addresses, cookies, or account details.
- Personal data is not used for testing or development.
Annex 2: Sub-processors
- Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany: hosting the server and database, in the European Union.
- Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA: DNS, encrypted connections, protection against attacks, and storage of database backups. Transfers: EU–US Data Privacy Framework and standard contractual clauses.
- Sendinblue SAS (Brevo), 106 boulevard Haussmann, 75008 Paris, France: sending the Service's emails.
- Functional Software, Inc. (Sentry), 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA: error reports, stored in the European Union data region. Transfers: EU–US Data Privacy Framework and standard contractual clauses.